{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/sparsity-based-defense-against-adversarial","title":"Sparsity-based Defense against Adversarial Attacks on Linear Classifiers","arxiv_id":"1801.04695","date":"2018-01-15","proceeding":null,"authors":["Zhinus Marzi","Soorya Gopalakrishnan","Upamanyu Madhow","Ramtin Pedarsani"],"abstract":"Deep neural networks represent the state of the art in machine learning in a\ngrowing number of fields, including vision, speech and natural language\nprocessing. However, recent work raises important questions about the\nrobustness of such architectures, by showing that it is possible to induce\nclassification errors through tiny, almost imperceptible, perturbations.\nVulnerability to such \"adversarial attacks\", or \"adversarial examples\", has\nbeen conjectured to be due to the excessive linearity of deep networks. In this\npaper, we study this phenomenon in the setting of a linear classifier, and show\nthat it is possible to exploit sparsity in natural data to combat\n$\\ell_{\\infty}$-bounded adversarial perturbations. Specifically, we demonstrate\nthe efficacy of a sparsifying front end via an ensemble averaged analysis, and\nexperimental results for the MNIST handwritten digit database. To the best of\nour knowledge, this is the first work to show that sparsity provides a\ntheoretically rigorous framework for defense against adversarial attacks.","url_abs":"http://arxiv.org/abs/1801.04695v3","url_pdf":"http://arxiv.org/pdf/1801.04695v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"sparsity-based-defense-against-adversarial","repo_url":"https://github.com/soorya19/sparsity-based-defenses","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":null},{"paper_slug":"sparsity-based-defense-against-adversarial","repo_url":"https://github.com/ZhinusMarzi/Adversarial-attack","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":null},{"paper_slug":"sparsity-based-defense-against-adversarial","repo_url":"https://github.com/ZhinusMarzi/Sparsity-based-defenses-against-adversarial-attacks","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}